Live data from Hacker News

Response to “WireGuard: great protocol, but skip the Mac app”

lists.zx2c4.com

211–220 of 392 posts

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#212
post #144

Earlier quoted context omitted.

Android is open source.

Only by the letter of the law, the android that ends up on your phone consists of mostly closed source binaries from Google that you don't get without installing the play store as well.

You mean the Google add-ons to Android.

Regular Android works great in GrapheneOS/CalyxOS/other AOSP variants.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#213

In an alternative universe, one could imagine macOS developers being so frustrated that they only bother with updating their windows/linux versions. In which case, only apps like parallels would have to be working, then the bugs of macOS could be bypassed for many and focused for a set of well-funded developers. All apps would have a translation layer, but that seems to not be an issue with the m1.

[deleted]

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#214

Earlier quoted context omitted.

What is your point? This kind of response completely ignores the fact that the vast majority of the drivers required to just run on modern hardware are closed source and that the vast majority of phones these days have their bootloaders locked.

> that the vast majority of phones these days have their bootloaders locked. I don't know if that is actually still true. Back in the day nearly every phone in the US was bootloader and carrier locked. Now basically every phone is carrier unlocked and anything besides Samsung can have the bootloader unlocked very easily. I guess Samsung phones are the most common but there are certainly many other options that are mo…

This seemed unlikely since S10 is maybe the most mainstream flagship phone but it appears that Samsung does indeed make it painful to take control of your device: https://topjohnwu.github.io/Magisk/install.html#samsung-syst...

Many manufactures make it easy to unlock and root your device (shout-out oneplus), but many others do try to make you brick it if you try doing anything out of the ordinary. Like the HMD rebrands Nokia, Sharp, etc.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#215
Apple doesn't deserve to have such careful and detail-oriented FOSS developers like Jason, developing for their platform. He is genuinely wasting time in order to work around Apple's developer-unfriendly platform. Not that I should be telling devs where they should spend their time... but I feel like so much effort is being devoted to fix Apple's issues.

> When I'm debugging these issues, I'll often times spend a few hours in IDA Pro (Apple doesn't provide debug symbols, unlike Microsoft, which makes this process even more miserable than it already is), and after identifying the issue I'll often have several ideas for "clever" workarounds. Which of them are acceptable for the App Store? Usually none!

Really, why we need to have very talented people spending their time in dealing with this, instead of contributing actual value on other parts of the project? Apple should be losing devs in favor of other better platforms, not the other way around. With less and worse products at their disposal, Apple users would then be well aware that they are choosing a platform that alienates developers.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#216

Earlier quoted context omitted.

Right. And Rachelbythebay is way more technically inclined than most users; if she wasn't able to correctly apply the blame to Apple, then normal users are definitely not going to be able to do that. Developers need to be more up-front about why these issues exist, we need an education push. For all the criticism about how Fortnight framed its issues on iOS (and some of that criticism was warranted), coming out of th…

> if she wasn't able to correctly apply the blame to Apple, then normal users are definitely not going to be able to do that This isn’t a moral judgement. I apply the blame to Apple. But I also choose to keep using their product. Their products are less dispensable to me than another VPN protocol.

People have been choosing usability over security forever - don't be ashamed.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#217
post #72

Earlier quoted context omitted.

Aeah, how much more proprietary and strange are the Apple API's going to get? They'll have control over the entire vertical, and can put all kinds of undocumented crap right in the silicon.

even to the syscall level, like the MAP_JIT flag to mmap() https://developer.apple.com/documentation/bundleresources/en... not optional and requires special app entitlements to enable. So you are not going to write portable code that has a JIT without apple-special code.

A JIT is a major potential source of malware enablement and thus a security consideration.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#218
One problematic thing about App Store reviews as a developer is on each submission, Apple does a cursory review of the whole app. This means a one-line bug fix that is an improvement in anyone’s eyes can get caught on a detail that has been present for years.

It would be fine if these complaints about old details were reported to developers as “blocking any future app releases”, but blocking immediate bug fixes really hurts.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#219

App Store gatekeeping needs to burn. It may be helpful for the tech-illiterate who want simple and safe apps, but it's not a viable for a healthy ecosystem of broad ranging applications. It's crazy to think I can't install an app from a developer I trust from their website.

You can disable Gatekeeper.

Re: Response to “WireGuard: great protocol, but skip the Mac app”

#220
post #2

That is a fantastic showcase how to respond to negative criticism in a friendly, constructive and polite manner. Good work, Jason.

Yup. I rarely use WireGuard but it’s a great app and the response here made me go and donate on their website.
Post reply on HN